[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fNtxZ5sciol3i2qB6-ca3Z-SSZNPmh7L7G63k_0Kj2wY":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1184,"What is the role of Capcom.sys in privilege escalation, and how is it exploited?","Capcom.sys is a legitimate driver from Capcom's Street Fighter V that contains a vulnerability allowing kernel code execution. After loading the driver using `sc create Capcom type= kernel binPath= C:\\test\\Capcom.sys` and starting it, an exploit program (e.g., ExploitCapcom) can be run even with regular user privileges to gain SYSTEM access. This method is specifically for x64 Windows 7 systems. See the [Capcom.sys section](\u002Fnews\u002Fpenetration-techniques-switching-from-admin-privileges-to-system-privileges#0x05) for details.","\u003Cp>Capcom.sys is a legitimate driver from Capcom&#39;s Street Fighter V that contains a vulnerability allowing kernel code execution. After loading the driver using `sc create Capcom type= kernel binPath= C:\\test\\Capcom.sys` and starting it, an exploit program (e.g., ExploitCapcom) can be run even with regular user privileges to gain SYSTEM access. This method is specifically for x64 Windows 7 systems. See the [Capcom.sys section](\u002Fnews\u002Fpenetration-techniques-switching-from-admin-privileges-to-system-privileges#0x05) for details.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-switching-from-admin-privileges-to-system-privileges\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-role-of-capcomsys-in-privilege-escalation-and-how-is-it-exploited-1777480204664","Capcom.sys, kernel exploit, driver vulnerability, privilege escalation, Windows 7 x64",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},287,"Penetration Techniques - Switching from Admin Privileges to System Privileges","penetration-techniques-switching-from-admin-privileges-to-system-privileges","Learn methods to switch from admin to system privileges in penetration testing, including service creation, MSIExec, token duplication, and Capcom.sys techniques.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, there are situations where System privileges are required, such as when manipulating the registry key HKEY_LOCAL_MACHINE\\SAM\\SAM.\u003C\u002Fp>\u003Cp>Coincidentally, I recently came across an article introducing several methods to obtain System privileges, so I decided to systematically organize these techniques based on my own experience.\u003C\u002Fp>\u003Cp>Of course, the prerequisite is that you have already obtained administrator privileges on the system.\u003C\u002Fp>\u003Cp>Reference link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.xpnsec.com\u002Fbecoming-system\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Method to obtain System privileges by creating a service\u003C\u002Fli>\u003Cli>Method to obtain System privileges using MSIExec\u003C\u002Fli>\u003Cli>Method to obtain System privileges using token duplication\u003C\u002Fli>\u003Cli>Method to obtain System privileges using Capcom.sys\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Obtain System Privileges by Creating a Service\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using the sc Command\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sc Create TestService1 binPath= \"cmd \u002Fc start\" type= own type= interact\u003Cbr>sc start TestService1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This method works on XP systems.\u003C\u002Fp>\u003Cp>On Win7, the console displays:\u003C\u002Fp>\u003Cp>Warning: The TestService1 service is configured as an interactive service, and its support is being deprecated. The service may not function properly.\u003C\u002Fp>\u003Cp>A dialog box appears when the service starts; you need to click 'View Message' to execute the code, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016714668_0_53934fc8ba.jpeg\">\u003C\u002Fp>\u003Cp>On Win8, the console displays an error, and this method cannot be used.\u003C\u002Fp>\u003Ch3>2. Using Scheduled Tasks\u003C\u002Fh3>\u003Cp>Using the at command:\u003C\u002Fp>\u003Cp>at 7:50 notepad.exe\u003C\u002Fp>\u003Cp>Starts with System privileges by default, applicable to Win7.\u003C\u002Fp>\u003Cp>Starting from Windows 8, the at command is no longer supported\u003C\u002Fp>\u003Cp>Use the schtasks command:\u003C\u002Fp>\u003Cp>Create a service to start with system privileges:\u003C\u002Fp>\u003Cp>schtasks \u002FCreate \u002FTN TestService2 \u002FSC DAILY \u002FST 00:36 \u002FTR notepad.exe \u002FRU SYSTEM\u003C\u002Fp>\u003Cp>Check service status:\u003C\u002Fp>\u003Cp>schtasks \u002FQuery \u002FTN TestService2\u003C\u002Fp>\u003Cp>Delete service:\u003C\u002Fp>\u003Cp>schtasks \u002FDelete \u002FTN TestService2 \u002FF\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Remember to manually delete services created with schtasks\u003C\u002Fp>\u003Cp>The schtasks command supports Windows 7 to Windows 10\u003C\u002Fp>\u003Ch3>3. Using psexec\u003C\u002Fh3>\u003Cp>Using psexec creates the PSEXESVC service, generating logs Event 4697, Event 7045, Event 4624, and Event 4652\u003C\u002Fp>\u003Cp>Start with system privileges:\u003C\u002Fp>\u003Cp>psexec.exe -accepteula -s -d notepad.exe\u003C\u002Fp>\u003Cp>By default, processes with system privileges do not display on the user desktop. If you need to display the process interface, you can add the \u002Fi parameter. The command is as follows:\u003C\u002Fp>\u003Cp>psexec.exe -accepteula -s -i -d notepad.exe\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016717668_1_18e47d670e.jpeg\">\u003C\u002Fp>\u003Ch3>4. Meterpreter\u003C\u002Fh3>\u003Cp>Refer to the Meterpreter method:\u003C\u002Fp>\u003Cul>\u003Cli>Create a service with system privileges and provide a named pipe\u003C\u002Fli>\u003Cli>Create a process and connect to that named pipe\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fxpn\u002Fgetsystem-offline\u003C\u002Fp>\u003Cp>Requires getsystem-offline.exe and getsystem_service.exe\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016724138_2_4e6c174beb.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Direct compilation in vs2012 has a bug; you can replace the function snprintf with _snprintf.\u003C\u002Fp>\u003Ch2>0x03 Gaining System Privileges via MSIExec\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>I previously introduced the method of creating msi files using Advanced Installer in the article \"MSIExec in Penetration Testing\", which won't be reiterated here.\u003C\u002Fp>\u003Cp>This section reproduces the method mentioned by XPN, using wix3 to create msi files.\u003C\u002Fp>\u003Cp>wix3 download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fwixtoolset\u002Fwix3\u003C\u002Fp>\u003Cp>The code for msigen.wix can be referenced at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002Fxpn\u002Fd1ef20dfd266053227d3e992ae84c64e\u003C\u002Fp>\u003Cp>The compilation commands are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>candle.exe msigen.wix\u003Cbr>torch.exe msigen.wixobj\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>I modified XPN's code by replacing the payload with the execution of calc.exe, with some detailed modifications. The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\"?-->\u003Cbr>\u003Cwix xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fwix\u002F2006\u002Fwi\">\u003Cbr>  \u003Cproduct id=\"*\" upgradecode=\"12345678-1234-1234-1234-111111111111\" name=\"Example Product \u003Cbr>Name\" version=\"0.0.1\" manufacturer=\"@_xpn_\" language=\"1033\">\u003Cbr>    \u003Cpackage installerversion=\"200\" compressed=\"yes\" comments=\"Windows Installer Package\">\u003Cbr>    \u003Cmedia id=\"1\">\u003Cbr>\u003Cbr>    \u003Cdirectory id=\"TARGETDIR\" name=\"SourceDir\">\u003Cbr>      \u003Cdirectory id=\"ProgramFilesFolder\">\u003Cbr>        \u003Cdirectory id=\"INSTALLLOCATION\" name=\"Example\">\u003Cbr>          \u003Ccomponent id=\"ApplicationFiles\" guid=\"12345678-1234-1234-1234-222222222222\">     \u003Cbr>          \u003C\u002Fcomponent>\u003Cbr>        \u003C\u002Fdirectory>\u003Cbr>      \u003C\u002Fdirectory>\u003Cbr>    \u003C\u002Fdirectory>\u003Cbr>\u003Cbr>    \u003Cfeature id=\"DefaultFeature\" level=\"1\">\u003Cbr>      \u003Ccomponentref id=\"ApplicationFiles\">\u003Cbr>    \u003C\u002Fcomponentref>\u003C\u002Ffeature>\u003Cbr>\u003Cbr>    \u003Cproperty id=\"cmdline\">calc.exe\u003Cbr>    \u003C\u002Fproperty>\u003Cbr>\u003Cbr>    \u003Ccustomaction id=\"SystemShell\" execute=\"deferred\" directory=\"TARGETDIR\" \u003Cbr=\"\">ExeCommand='[cmdline]' Return=\"ignore\" Impersonate=\"no\"\u002F&gt;\u003Cbr>\u003Cbr>    \u003Ccustomaction id=\"FailInstall\" execute=\"deferred\" script=\"vbscript\" return=\"check\">\u003Cbr>      invalid vbs to fail install\u003Cbr>    \u003C\u002Fcustomaction>\u003Cbr>\u003Cbr>    \u003Cinstallexecutesequence>\u003Cbr>      \u003Ccustom action=\"SystemShell\" after=\"InstallInitialize\">\u003C\u002Fcustom>\u003Cbr>      \u003Ccustom action=\"FailInstall\" before=\"InstallFiles\">\u003C\u002Fcustom>\u003Cbr>    \u003C\u002Finstallexecutesequence>\u003Cbr>\u003Cbr>  \u003C\u002Fcustomaction>\u003C\u002Fmedia>\u003C\u002Fpackage>\u003C\u002Fproduct>\u003Cbr>\u003C\u002Fwix>\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Based on my testing, using torch.exe to compile msigen.wixobj into msigen.msi file will result in an error, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016729849_3_db1238fb83.jpeg\">\u003C\u002Fp>\u003Cp>Using light.exe can successfully generate msigen.msi, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016734418_4_695eace019.jpeg\">\u003C\u002Fp>\u003Cp>Although an error is reported, it does not affect file generation and function execution\u003C\u002Fp>\u003Cp>That is to say, the complete compilation commands are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>candle.exe msigen.wix\u003Cbr>light.exe msigen.wixobj\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Double-clicking msigen.msi directly will pop up a dialog, and the launched calc.exe runs with system privileges\u003C\u002Fp>\u003Cp>Execute from the command line:\u003C\u002Fp>\u003Cp>msiexec \u002Fq \u002Fi msigen.msi\u003C\u002Fp>\u003Cp>The launched calc.exe runs with high privileges\u003C\u002Fp>\u003Ch2>0x04 Exploiting Token Duplication to Obtain System Privileges\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>You can refer to the previous article: \"Penetration Techniques – Token Theft and Exploitation\"\u003C\u002Fp>\u003Cp>By duplicating a system-privileged token, the process gains system privileges. Commonly used tools are as follows:\u003C\u002Fp>\u003Ch3>1、incognito\u003C\u002Fh3>\u003Cp>incognito.exe execute -c \"NT AUTHORITY\\SYSTEM\" cmd.exe\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Flabs.mwrinfosecurity.com\u002Fassets\u002FBlogFiles\u002Fincognito2.zip\u003C\u002Fp>\u003Ch3>2、Invoke-TokenManipulation.ps1\u003C\u002Fh3>\u003Cp>Invoke-TokenManipulation -CreateProcess \"cmd.exe\" -Username \"nt authority\\system\"\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FExfiltration\u002FInvoke-TokenManipulation.ps1\u003C\u002Fp>\u003Ch3>3、SelectMyParent\u003C\u002Fh3>\u003Cp>SelectMyParent.exe cmd.exe 504\u003C\u002Fp>\u003Cp>Reference link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Author: Didier Stevens\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The principle of SelectMyParent is the same as the code open-sourced by xpn (PROC_THREAD_ATTRIBUTE_PARENT_PROCESS method), link as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002Fxpn\u002Fa057a26ec81e736518ee50848b9c2cd6\u003C\u002Fp>\u003Ch2>0x05 Method to obtain System privileges using Capcom.sys\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Capcom.sys is an anti-cheat driver from Capcom's game 'Street Fighter V', bearing Capcom's signature, containing vulnerabilities that allow kernel code execution\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>SHA1: c1d5cf8c43e7679b782630e93f5e6420ca1749a7\u003C\u002Fp>\u003Cp>Compatible with Win7x64\u003C\u002Fp>\u003Cp>1. Create a service in the current system\u003C\u002Fp>\u003Cp>Administrator privileges required\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sc create Capcom type= kernel binPath= C:\\test\\Capcom.sys\u003Cbr>sc start Capcom\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Execute the exploit program\u003C\u002Fp>\u003Cp>Regular user privileges suffice\u003C\u002Fp>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ftandasat\u002FExploitCapcom\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article compiles common methods for obtaining System privileges, and finally, thanks to xpn's blog and his open-source code.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, there are situations where System privileges are required, such as when manipulating the registry key HKEY_LOCAL_MACHINE\\SAM\\SAM.\u003C\u002Fp>\u003Cp>Coincidentally, I recently came across an article introducing several methods to obtain System privileges, so I decided to systematically organize these techniques based on my own experience.\u003C\u002Fp>\u003Cp>Of course, the prerequisite is that you have already obtained administrator privileges on the system.\u003C\u002Fp>\u003Cp>Reference link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.xpnsec.com\u002Fbecoming-system\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Method to obtain System privileges by creating a service\u003C\u002Fli>\u003Cli>Method to obtain System privileges using MSIExec\u003C\u002Fli>\u003Cli>Method to obtain System privileges using token duplication\u003C\u002Fli>\u003Cli>Method to obtain System privileges using Capcom.sys\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Obtain System Privileges by Creating a Service\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using the sc Command\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sc Create TestService1 binPath= \"cmd \u002Fc start\" type= own type= interact\u003Cbr>sc start TestService1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This method works on XP systems.\u003C\u002Fp>\u003Cp>On Win7, the console displays:\u003C\u002Fp>\u003Cp>Warning: The TestService1 service is configured as an interactive service, and its support is being deprecated. The service may not function properly.\u003C\u002Fp>\u003Cp>A dialog box appears when the service starts; you need to click 'View Message' to execute the code, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016714668_0_53934fc8ba-1.jpeg\">\u003C\u002Fp>\u003Cp>On Win8, the console displays an error, and this method cannot be used.\u003C\u002Fp>\u003Ch3>2. Using Scheduled Tasks\u003C\u002Fh3>\u003Cp>Using the at command:\u003C\u002Fp>\u003Cp>at 7:50 notepad.exe\u003C\u002Fp>\u003Cp>Starts with System privileges by default, applicable to Win7.\u003C\u002Fp>\u003Cp>Starting from Windows 8, the at command is no longer supported\u003C\u002Fp>\u003Cp>Use the schtasks command:\u003C\u002Fp>\u003Cp>Create a service to start with system privileges:\u003C\u002Fp>\u003Cp>schtasks \u002FCreate \u002FTN TestService2 \u002FSC DAILY \u002FST 00:36 \u002FTR notepad.exe \u002FRU SYSTEM\u003C\u002Fp>\u003Cp>Check service status:\u003C\u002Fp>\u003Cp>schtasks \u002FQuery \u002FTN TestService2\u003C\u002Fp>\u003Cp>Delete service:\u003C\u002Fp>\u003Cp>schtasks \u002FDelete \u002FTN TestService2 \u002FF\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Remember to manually delete services created with schtasks\u003C\u002Fp>\u003Cp>The schtasks command supports Windows 7 to Windows 10\u003C\u002Fp>\u003Ch3>3. Using psexec\u003C\u002Fh3>\u003Cp>Using psexec creates the PSEXESVC service, generating logs Event 4697, Event 7045, Event 4624, and Event 4652\u003C\u002Fp>\u003Cp>Start with system privileges:\u003C\u002Fp>\u003Cp>psexec.exe -accepteula -s -d notepad.exe\u003C\u002Fp>\u003Cp>By default, processes with system privileges do not display on the user desktop. If you need to display the process interface, you can add the \u002Fi parameter. The command is as follows:\u003C\u002Fp>\u003Cp>psexec.exe -accepteula -s -i -d notepad.exe\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016717668_1_18e47d670e-1.jpeg\">\u003C\u002Fp>\u003Ch3>4. Meterpreter\u003C\u002Fh3>\u003Cp>Refer to the Meterpreter method:\u003C\u002Fp>\u003Cul>\u003Cli>Create a service with system privileges and provide a named pipe\u003C\u002Fli>\u003Cli>Create a process and connect to that named pipe\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fxpn\u002Fgetsystem-offline\u003C\u002Fp>\u003Cp>Requires getsystem-offline.exe and getsystem_service.exe\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016724138_2_4e6c174beb-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Direct compilation in vs2012 has a bug; you can replace the function snprintf with _snprintf.\u003C\u002Fp>\u003Ch2>0x03 Gaining System Privileges via MSIExec\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>I previously introduced the method of creating msi files using Advanced Installer in the article \"MSIExec in Penetration Testing\", which won't be reiterated here.\u003C\u002Fp>\u003Cp>This section reproduces the method mentioned by XPN, using wix3 to create msi files.\u003C\u002Fp>\u003Cp>wix3 download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fwixtoolset\u002Fwix3\u003C\u002Fp>\u003Cp>The code for msigen.wix can be referenced at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002Fxpn\u002Fd1ef20dfd266053227d3e992ae84c64e\u003C\u002Fp>\u003Cp>The compilation commands are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>candle.exe msigen.wix\u003Cbr>torch.exe msigen.wixobj\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>I modified XPN's code by replacing the payload with the execution of calc.exe, with some detailed modifications. The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\"?-->\u003Cbr>\u003Cwix xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fwix\u002F2006\u002Fwi\">\u003Cbr>  \u003Cproduct id=\"*\" upgradecode=\"12345678-1234-1234-1234-111111111111\" name=\"Example Product \u003Cbr>Name\" version=\"0.0.1\" manufacturer=\"@_xpn_\" language=\"1033\">\u003Cbr>    \u003Cpackage installerversion=\"200\" compressed=\"yes\" comments=\"Windows Installer Package\">\u003Cbr>    \u003Cmedia id=\"1\">\u003Cbr>\u003Cbr>    \u003Cdirectory id=\"TARGETDIR\" name=\"SourceDir\">\u003Cbr>      \u003Cdirectory id=\"ProgramFilesFolder\">\u003Cbr>        \u003Cdirectory id=\"INSTALLLOCATION\" name=\"Example\">\u003Cbr>          \u003Ccomponent id=\"ApplicationFiles\" guid=\"12345678-1234-1234-1234-222222222222\">     \u003Cbr>          \u003C\u002Fcomponent>\u003Cbr>        \u003C\u002Fdirectory>\u003Cbr>      \u003C\u002Fdirectory>\u003Cbr>    \u003C\u002Fdirectory>\u003Cbr>\u003Cbr>    \u003Cfeature id=\"DefaultFeature\" level=\"1\">\u003Cbr>      \u003Ccomponentref id=\"ApplicationFiles\">\u003Cbr>    \u003C\u002Fcomponentref>\u003C\u002Ffeature>\u003Cbr>\u003Cbr>    \u003Cproperty id=\"cmdline\">calc.exe\u003Cbr>    \u003C\u002Fproperty>\u003Cbr>\u003Cbr>    \u003Ccustomaction id=\"SystemShell\" execute=\"deferred\" directory=\"TARGETDIR\" \u003Cbr=\"\">ExeCommand='[cmdline]' Return=\"ignore\" Impersonate=\"no\"\u002F&gt;\u003Cbr>\u003Cbr>    \u003Ccustomaction id=\"FailInstall\" execute=\"deferred\" script=\"vbscript\" return=\"check\">\u003Cbr>      invalid vbs to fail install\u003Cbr>    \u003C\u002Fcustomaction>\u003Cbr>\u003Cbr>    \u003Cinstallexecutesequence>\u003Cbr>      \u003Ccustom action=\"SystemShell\" after=\"InstallInitialize\">\u003C\u002Fcustom>\u003Cbr>      \u003Ccustom action=\"FailInstall\" before=\"InstallFiles\">\u003C\u002Fcustom>\u003Cbr>    \u003C\u002Finstallexecutesequence>\u003Cbr>\u003Cbr>  \u003C\u002Fcustomaction>\u003C\u002Fmedia>\u003C\u002Fpackage>\u003C\u002Fproduct>\u003Cbr>\u003C\u002Fwix>\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Based on my testing, using torch.exe to compile msigen.wixobj into msigen.msi file will result in an error, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016729849_3_db1238fb83-1.jpeg\">\u003C\u002Fp>\u003Cp>Using light.exe can successfully generate msigen.msi, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016734418_4_695eace019-1.jpeg\">\u003C\u002Fp>\u003Cp>Although an error is reported, it does not affect file generation and function execution\u003C\u002Fp>\u003Cp>That is to say, the complete compilation commands are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>candle.exe msigen.wix\u003Cbr>light.exe msigen.wixobj\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Double-clicking msigen.msi directly will pop up a dialog, and the launched calc.exe runs with system privileges\u003C\u002Fp>\u003Cp>Execute from the command line:\u003C\u002Fp>\u003Cp>msiexec \u002Fq \u002Fi msigen.msi\u003C\u002Fp>\u003Cp>The launched calc.exe runs with high privileges\u003C\u002Fp>\u003Ch2>0x04 Exploiting Token Duplication to Obtain System Privileges\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>You can refer to the previous article: \"Penetration Techniques – Token Theft and Exploitation\"\u003C\u002Fp>\u003Cp>By duplicating a system-privileged token, the process gains system privileges. Commonly used tools are as follows:\u003C\u002Fp>\u003Ch3>1、incognito\u003C\u002Fh3>\u003Cp>incognito.exe execute -c \"NT AUTHORITY\\SYSTEM\" cmd.exe\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Flabs.mwrinfosecurity.com\u002Fassets\u002FBlogFiles\u002Fincognito2.zip\u003C\u002Fp>\u003Ch3>2、Invoke-TokenManipulation.ps1\u003C\u002Fh3>\u003Cp>Invoke-TokenManipulation -CreateProcess \"cmd.exe\" -Username \"nt authority\\system\"\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FExfiltration\u002FInvoke-TokenManipulation.ps1\u003C\u002Fp>\u003Ch3>3、SelectMyParent\u003C\u002Fh3>\u003Cp>SelectMyParent.exe cmd.exe 504\u003C\u002Fp>\u003Cp>Reference link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Author: Didier Stevens\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The principle of SelectMyParent is the same as the code open-sourced by xpn (PROC_THREAD_ATTRIBUTE_PARENT_PROCESS method), link as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002Fxpn\u002Fa057a26ec81e736518ee50848b9c2cd6\u003C\u002Fp>\u003Ch2>0x05 Method to obtain System privileges using Capcom.sys\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Capcom.sys is an anti-cheat driver from Capcom's game 'Street Fighter V', bearing Capcom's signature, containing vulnerabilities that allow kernel code execution\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>SHA1: c1d5cf8c43e7679b782630e93f5e6420ca1749a7\u003C\u002Fp>\u003Cp>Compatible with Win7x64\u003C\u002Fp>\u003Cp>1. Create a service in the current system\u003C\u002Fp>\u003Cp>Administrator privileges required\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sc create Capcom type= kernel binPath= C:\\test\\Capcom.sys\u003Cbr>sc start Capcom\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Execute the exploit program\u003C\u002Fp>\u003Cp>Regular user privileges suffice\u003C\u002Fp>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ftandasat\u002FExploitCapcom\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article compiles common methods for obtaining System privileges, and finally, thanks to xpn's blog and his open-source code.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",32,"Onedaysec",4,"published","2026-02-02T07:25:19.685Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Switch Admin to System Privileges: Penetration Testing Techniques","penetration testing, system privileges, admin to system, privilege escalation, sc command, psexec, scheduled tasks, MSIExec, token duplication, Capcom.sys",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],1185,1183,1182,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.034Z","2026-07-23T16:02:39.212Z","draft","2026-07-23T16:17:14.963Z"]